Rewterz
Rewterz Threat Advisory – CVE-2021-1287 – Cisco Small Business RV132W and RV134W Routers Management Interface Vulnerability
March 19, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-3428 – Linux Kernel denial of service
March 19, 2021

Rewterz Threat Advisory – Multiple Adobe Security Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-21089

Adobe Acrobat and Adobe Reader could allow a remote attacker to gain elevated privileges on the system, caused by an out-of-bounds read error within the handling of URIs by weblink.api. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.

CVE-2021-21088

Adobe Acrobat and Adobe Reader could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error within the colorConvertPage method. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.

CVE-2021-21086

Adobe Acrobat and Adobe Reader could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.

Impact

  • Gain Privileges
  • Arbitrary code execution

Affected Vendors

Adobe

Affected Products

  • Adobe Acrobat 2017 2017.011.30188
  • Adobe Acrobat 2020 20.001.30018
  • Adobe Acrobat 2020 20.001.30018

Remediation

Refer to Adobe Security Bulletin APSB21-09 for patch, upgrade or suggested workaround information.

Adobe Security Bulletin APSB21-09